FORTINET’S FortiGuard Incident Response (FGIR) team has uncovered a SectopRAT, also known as ArechClient2, infection targeting Windows systems. The malware was concealed in a locally modified legitimate audio reporting tool, rather than being distributed through a confirmed vendor supply-chain compromise. Investigators found tampered `FrameworkBase.dll` and an added malicious `sdkcra.dll` in the Windows `ProgramData` directory, alongside a scheduled task that automatically launched `ReportDump.exe` for persistence.
When executed, the altered application loads encrypted payloads from `Activation.Desktop.db` and `pool.db`. The loader uses the Windows `EnumSystemCodePagesW` function to execute decrypted code and employs API hashing to resolve 187 system functions. Obfuscation, control-flow flattening and in-memory execution are used to make analysis and detection more difficult. SectopRAT retrieves its command-and-control address from encrypted resources, with twelve backup domains used during alternative discovery. Its communications are symmetrically encrypted and stolen data is sent in JSON format.
The backdoor supports 29 commands, including process manipulation, desktop capture, remote shell execution, host restarting and self-removal. A further module, `WbElevation.dll`, can steal credentials, autofill data, cookies and payment-card information from more than 35 browsers, including Chrome, Edge, Firefox, Brave and Opera. It also targets Thunderbird and wallets such as MetaMask, Exodus and Atomic Wallet.
FGIR says attribution is unconfirmed, although the focus on financial information suggests financially motivated criminals. Recommended detection includes monitoring unexpected executables and imports in `ProgramData`, suspicious shell activity, unusual code-page enumeration and traffic to known command-and-control infrastructure.